CBIZ

Insights. Applied. Integrated solutions that turn strategy into action.

  • Article
September 30, 2026

Minimum Controls for Cyber Insurance—How are They Changing and Why?

Minimum Controls for Cyber Insurance—How are They Changing and Why?
Table of Contents

Cyber insurers now expect a stronger baseline control set coupled with more intensive due diligence prior to granting or renewing coverage. Organizations with mature cybersecurity postures and clean claims histories will enjoy lower premiums that reflect their favorable cyber risk profiles.

This article explains emerging control requirements and coverage/cost factors along with verification process changes.

Key takeaways

  • Major shifts in the cyber insurance market include broader baseline control requirements combined with more rigorous validation of cybersecurity programs.
  • Top change drivers in the cyber insurance space include AI-powered attacks, combining cyber coverage with managed services, and an intensified threat actor focus on small to midsized businesses (SMBs).
  • Cyber controls that underwriters increasingly see as a prerequisite for coverage include multifactor authentication (MFA), managed detection/response (MDR), ransomware-proof backups, a documented incident response plan, reliable patch management, zero-trust access controls, vendor risk management, robust file retention practices, and security awareness training.
  • Insurers are expecting robust AI governance and risk management programs, treating them as a “best practice” that affects the insured’s risk profile.
  • Understanding what cyber insurance carriers want and meeting their requirements to optimize coverage and reduce risk has become a strategic business consideration.

What are the top change drivers now shaping the cyber insurance market?

The cyber insurance market for SMBs is transforming in two important ways:

  1. Insurers’ verification of organizations’ cybersecurity postures is shifting from self-report checklists to real-time, data-driven validation of control operation including technical evidence, logs, and third-party vulnerability scans and penetration testing.
  2. The baseline control set to qualify for coverage has become more robust and holistic, with premiums increasingly tied to confirmed cybersecurity status.

The top change drivers moving the SMB cyber insurance landscape in this direction include:

  • Greater cybercrime focus on SMBs as “softer targets” as enterprises batten down their attack surfaces.
  • AI-powered malware and phishing scams that are increasing SMB attack frequency, massively accelerating attack chains, and making attacks more effective.
  • Overall softening or stabilizing of cyber insurance premiums offset by more intense client scrutiny, stricter coverage conditions, and the rejection of higher-risk applicants.
  • Combining cyber insurance coverage with managed IT services or cybersecurity products.

In the wake of costly claims from ransomware attacks and other incidents, insurers are looking to reduce the number of preventable data breaches through more rigorous process of assessing clients’ cyber sophistication. Lack of required protections may increasingly be viewed as posing an unacceptable liability.

What baseline controls do SMBs need to qualify for cyber insurance today?

Specific technical and documentation requirements vary for different insurers and policy types. Today, the essential cybersecurity controls that SMBs need to avoid premium penalties, coverage exclusions, or outright coverage denial commonly include:

  • MFA for all users across all critical systems, including privileged/admin accounts, cloud services, email systems, and remote access services. Companies should be prepared to show evidence that MFA is in place and operating. Those with weak MFA face substantial risk being denied coverage.
  • Advanced endpoint protection like endpoint detection and response (EDR), extended detection and response (XDR), or preferably managed detection and response (MDR). Antivirus solutions alone are insufficient. Capabilities should support monitoring, detecting, and responding to potential incidents, not just blocking known threats. Many insurers now want evidence that a qualified human is monitoring and acting on alerts 24×7 and the organization has a predefined incident response process in place.
  • Immutable or offline backups that are encrypted and tested regularly for rapid recovery from ransomware attacks. Just because a backup process is running does not mean the data is adequately protected from ransomware threats or can be restored within the recovery time objective.
  • A zero-trust operating model, especially network micro-segmentation, least privilege access, conditional authentication, and robust/granular access restrictions on high-risk assets. These requirements move the focus from tools to strategy, with underwriters seeking evidence of zero trust or least privilege principles operating in the client environment.
  • A documented incident response plan, because data breaches are now seen as inevitable. Insurers want proof that a business can minimize the damage and recovery time following an attack. Evidence of testing the incident response plan or conducting tabletop exercises at least annually is key.
  • A vendor/supply chain risk management program. The prevalence of supply chain attacks makes it imperative that businesses evaluate the cybersecurity postures of all vendors, contractors, or cloud service providers handling sensitive internal data. Insurers want proof that firms can effectively limit vendor and contractor data access and mitigate the highest third-party risks.
  • Patch and vulnerability management. Known, unpatched vulnerabilities in commercial software remain among the most prevalent data breach entry points. Insurers will look for documentation detailing when patches were applied.
  • Compliance-driven record retention policies. Maintain only those records legally required or critical to business operations to lower costs associated with meeting applicable state notification requirements.
  • Cybersecurity awareness training. Human error remains a leading contributor to successful cyber-attacks. Insurers look for documentation of training program delivery, including regular phishing simulations, especially for employees with access to sensitive data.

The overall trend is for more explicit coverage requirements, more intensive security assessments that include real-time operational data, and more emphasis on documentation (e.g., policies, logs, screenshots, evidence of backup testing, evidence of control operation). Reducing preventable incidents is a primary goal for insurers.

Insurers are most concerned about mitigating high-cost threats including AI-powered attacks, new/advanced ransomware variants, business email compromise (BEC) scams, and supply chain or third-party attacks.

In line with underwriters’ higher expectations, organizations that can demonstrate strong, comprehensive cybersecurity programs are better positioned to secure more favorable rates and coverages versus those that are seen as “doing the minimum.” Firms in higher-risk sectors (e.g., healthcare, financial services, retail, manufacturing) could face higher rates and restricted coverage terms, along with companies that have gaps in their security postures.

What about AI risks?

Organizations and cyber insurers both face the challenge of adapting to emerging AI risks and threats. These are becoming more prevalent alongside the rise of generative AI tools and automation—especially when AI is deployed without effective governance.

Potential AI risks of greatest concern include:

  • Weak AI access controls;
  • Inadequate visibility into AI use;
  • Automated decision-making without proper oversight;
  • Proliferation of shadow AI tools;
  • Entering sensitive data into public AI systems;
  • Sophisticated social engineering fraud and deep-fake schemes;
  • Unauthorized exposure of sensitive data or intellectual property; and
  • Biased, inaccurate, or harmful AI output/actions.

Insurers are increasingly evaluating AI policies and procedures to adequately address exposure to loss from AI-related incidents Where there is evidence of a lack of AI governance and risk management protocol, carriers may restrict coverage. Businesses that deploy AI should create an AI acceptable use policy, establish an approval process for AI tools (including citizen developed tools), provide employee training on AI use, and gain visibility into AI-related activity and risks in the environment.

Preparing for cyber resilience

Preparing for cyber resilience takes a coordinated approach that includes obtaining the right cyber insurance coverage for your business needs and risk profile. Organizations that view cyber insurance as part of their security program and understand the evaluation process and what underwriters require stand a much better chance of obtaining effective coverage. Firms that continue to approach cyber insurance with a checklist mentality may find it increasingly difficult to get the coverage they need.

Whether you are new to cyber insurance, concerned about an upcoming renewal, or have questions about how best to navigate today’s dynamic cyber insurance market, CBIZ can help you align your technical controls, insurance coverage, and response capabilities to minimize cyber incident risks and impacts.

© Copyright CBIZ, Inc. All rights reserved. Use of the material contained herein without the express written consent of the firms is prohibited by law. This publication is distributed with the understanding that CBIZ is not rendering legal, accounting or other professional advice. The reader is advised to contact a tax professional prior to taking any action based upon this information. CBIZ assumes no liability whatsoever in connection with the use of this information and assumes no obligation to inform the reader of any changes in tax laws or other factors that could affect the information contained herein. Material contained in this publication is informational and promotional in nature and not intended to be specific financial, tax or consulting advice. Readers are advised to seek professional consultation regarding circumstances affecting their organization.

“CBIZ” is the brand name under which CBIZ CPAs P.C. and CBIZ, Inc. and its subsidiaries, including CBIZ Advisors, LLC, provide professional services. CBIZ CPAs P.C. and CBIZ, Inc. (and its subsidiaries) practice as an alternative practice structure in accordance with the AICPA Code of Professional Conduct and applicable law, regulations, and professional standards. CBIZ CPAs P.C. is a licensed independent CPA firm that provides attest services to its clients. CBIZ, Inc. and its subsidiary entities provide tax, advisory, and consulting services to their clients. CBIZ, Inc. and its subsidiary entities are not licensed CPA firms and, therefore, cannot provide attest services.

Let’s Connect

Our team is here to help. Whether you’re looking for business solutions, financial strategies, or industry insights, we’re ready to collaborate. Fill out the form, and we’ll be in touch soon.

This field is for validation purposes and should be left unchanged.